A security vulnerability tracked as CVE-2026-4703 has been identified in the WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress, affecting all versions up to and including 1.10.80. The flaw is a code injection issue that allows unauthenticated attackers (people without login access to your WordPress site) to send specially crafted form submissions that introduce harmful PHP code objects into your site's system.
This specific vulnerability in the WS Form LITE plugin does not pose a direct risk on its own, as there is no built-in method for attackers to exploit the injected code using only this plugin. It only becomes a threat if you have another WordPress plugin or theme installed on your site that contains a related coding weakness. If such a weakness is present, an attacker could use this flaw to delete files on your site, access sensitive data, or run unauthorized code, with the exact impact depending on the nature of the weakness in the other plugin or theme.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703